Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2011-2532
The json.decode function in util/json.lua in Prosody 0.8.x before 0.8.1 might allow remote attackers to cause a denial of service (infinite loop) via…
Prosody
Patch available
MEDIUM 5.0
CVE-2011-2205
Prosody before 0.8.1 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory a…
Prosody
after 0.8.0
MEDIUM 5.0
CVE-2011-1756
modules/xmpp/serv_xmpp.c in Citadel 7.86 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cau…
Citadel
after 7.86
MEDIUM 5.0
CVE-2011-1757
DJabberd 0.84 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (mem…
Djabberd
after 0.84
MEDIUM 5.0
CVE-2011-2188
LuaExpat before 1.2.0 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory …
Luaexpat
after 1.1.0
MEDIUM 5.0
CVE-2011-1753
expat_erl.c in ejabberd before 2.1.7 and 3.x before 3.0.0-alpha-3, and exmpp before 0.9.7, does not properly detect recursion during entity expansion…
Ejabberd
after 2.1.6
MEDIUM 5.0
CVE-2011-1754
jabberd14 1.6.1.1 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service …
Jabberd14
after 1.6.1.1
HIGH 7.8
CVE-2011-1869EPSS 10%
The Distributed File System (DFS) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Ser…
Windows 2003 Server
Mitigation only
MEDIUM 5.0
CVE-2011-1952
common.php in Post Revolution before 0.8.0c-2 allows remote attackers to cause a denial of service (infinite loop) via malformed HTML markup, as demo…
Post Revolution
after 0.8.0c
MEDIUM 5.0
CVE-2009-4008
Unbound before 1.4.4 does not send responses for signed zones after mishandling an unspecified query, which allows remote attackers to cause a denial…
Unbound
after 1.4.3
MEDIUM 5.0
CVE-2011-1947
fetchmail 5.9.9 through 6.3.19 does not properly limit the wait time after issuing a (1) STARTTLS or (2) STLS request, which allows remote servers to…
Fetchmail
Mitigation only
HIGH 7.8
CVE-2011-1649
The Internet Streamer application in Cisco Content Delivery System (CDS) with software 2.5.7, 2.5.8, and 2.5.9 before build 126 allows remote attacke…
Content Delivery System Engine
Mitigation only
HIGH 7.8
CVE-2011-1651
Cisco IOS XR 3.9.x and 4.0.x before 4.0.3 and 4.1.x before 4.1.1, when an SPA interface processor is installed, allows remote attackers to cause a de…
Ios Xr
Mitigation only
HIGH 7.8
CVE-2011-0943
Cisco IOS XR 3.8.3, 3.8.4, and 3.9.1 allows remote attackers to cause a denial of service (NetIO process restart or device reload) via a crafted IPv4…
Ios Xr
Mitigation only
HIGH 7.8
CVE-2011-0949
Cisco IOS XR 3.6.x, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 does not properly remove sshd_lock files from /tmp/, which allows remote attackers to …
Ios Xr
Mitigation only
MEDIUM 5.0
CVE-2009-5024
ViewVC before 1.1.11 allows remote attackers to bypass the cvsdb row_limit configuration setting, and consequently conduct resource-consumption attac…
Viewvc
after 1.1.10
MEDIUM 5.8
CVE-2011-1575EPSS 33%
The STARTTLS implementation in ftp_parser.c in Pure-FTPd before 1.0.30 does not properly restrict I/O buffering, which allows man-in-the-middle attac…
Pure Ftpd
after 1.0.29
MEDIUM 6.8
CVE-2011-0723
FFmpeg 0.5.x, as used in MPlayer and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arb…
Ffmpeg
Mitigation only
MEDIUM 5.0
CVE-2011-2144
The eDocument Conversion Actions implementation in IBM Datacap Taskmaster Capture 8.0.1 FP1 and earlier allows remote attackers to cause a denial of …
Datacap Taskmaster Capture
after 8.0.1
HIGH 10.0
CVE-2011-1854EPSS 11%
Use-after-free vulnerability in HP Intelligent Management Center (IMC) 5.0 before E0101L02 allows remote attackers to execute arbitrary code via a lo…
Intelligent Management Center
Patch available
MEDIUM 5.0
CVE-2011-1907EPSS 5%
ISC BIND 9.8.x before 9.8.0-P1, when Response Policy Zones (RPZ) RRset replacement is enabled, allows remote attackers to cause a denial of service (…
Bind
Mitigation only
HIGH 10.0
CVE-2011-0066
Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers to execut…
Firefox
after 2.0.13
HIGH 10.0
CVE-2011-0065EPSS 74%
Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers to execut…
Firefox
after 2.0.13
MEDIUM 5.7
CVE-2011-0714
Use-after-free vulnerability in a certain Red Hat patch for the RPC server sockets functionality in the Linux kernel 2.6.32 on Red Hat Enterprise Lin…
Linux Kernel
Mitigation only
HIGH 7.8
CVE-2011-1785
VMware ESXi 4.0 and 4.1 and ESX 4.0 and 4.1 allow remote attackers to cause a denial of service (socket exhaustion) via unspecified network traffic.
Esx
Mitigation only
MEDIUM 5.0
CVE-2011-1786
lsassd in Likewise Open /Enterprise 5.3 before build 7845, Open 6.0 before build 8325, and Enterprise 6.0 before build 178, as distributed in VMware …
Esx
Mitigation only
HIGH 7.1
CVE-2011-1604
Memory leak in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5b)su3, 8.0 before 8.0(3a)s…
Unified Communications Manager
Mitigation only
MEDIUM 5.0
CVE-2011-1507
Asterisk Open Source 1.4.x before 1.4.40.1, 1.6.1.x before 1.6.1.25, 1.6.2.x before 1.6.2.17.3, and 1.8.x before 1.8.3.3 and Asterisk Business Editio…
Asterisk
Patch available
MEDIUM 6.8
CVE-2007-6742
The get_filter_list function in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0006 does not properly perform certain sub filter par…
Tivoli Directory Server
Patch available
MEDIUM 5.0
CVE-2008-7288
IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 on AIX allows remote attackers to cause a denial of service (server destabilizat…
Tivoli Directory Server
Mitigation only